Privacy Policy
This policy explains what personal data the DEAD AIR website collects, why, and what you can do about it. The site is run by the developer of DEAD AIR, the data controller. Contact: no-reply@ashbornestudios.com.
We don't sell your data, show ads, or use analytics or tracking scripts.
What we collect
- Your account: email address, display name and password. The password is stored only as an Argon2id hash, never in readable form. If you turn on two-factor sign-in, we store the authenticator secret (encrypted) and one-way hashes of your recovery codes.
- Sign-in sessions: a random token in a cookie (we store only a hash of it), when it expires, and your browser's user-agent string so you can recognise your sessions.
- Purchases and donations: what you bought, the amount, currency, any tax, promotion code, status and dates, the payment provider's reference numbers, and the payer email the provider reports. Card and bank details are entered on PayPal's or Stripe's own pages and never reach our servers. We keep the notifications the payment provider sends us about your payment, which can include your name, email and billing country or postcode.
- Your license: whether you have one, and which builds you downloaded and when.
- Comments you post on devlogs, with the time and your display name.
- Newsletter: your email address and when you signed up, confirmed or unsubscribed. This needs no account.
- Security: your IP address is used to limit how often forms can be submitted (against password guessing, spam and card testing). It's stored only inside short-lived counters, which are removed automatically after their time window (at most one day).
Why (legal bases)
- To run your account, deliver what you bought and send receipts and password resets: performing our contract with you.
- To keep purchase records for tax and accounting: our legal obligations.
- To protect the site, your account and payments from abuse: our legitimate interest in security.
- To send the newsletter, and to load YouTube videos: your consent, which you can withdraw at any time.
Who we share it with
Only these services, and only what they need to do their job for us:
- Our hosting provider, which runs the servers and database.
Some of these companies may process data outside your country. Where the law requires it, they do so under safeguards such as the European Commission's standard contractual clauses. We may also disclose data when required by law.
Cookies
The site itself sets only cookies it needs to work:
| Cookie | Purpose | Lasts |
|---|---|---|
| da_session (__Host-da_session over HTTPS) | Keeps you signed in | 30 days, or until you sign out |
| da_2fa (__Host-da_2fa over HTTPS) | Remembers that you entered your password while you type your two-factor code | 5 minutes |
| da_consent | Remembers your cookie choice | 1 year |
PayPal and Stripe may set their own cookies on their payment pages. YouTube videos are not loaded until you allow them (in the cookie banner) or press Play; YouTube may then set its own cookies. You can change your choice with “Cookie settings” at the bottom of every page.
How long we keep it
- Account data: until you ask us to delete your account.
- Purchase records: as long as tax and accounting law requires, even after an account is deleted.
- Sessions end after 30 days or when you sign out. Password reset links expire after 1 hour, newsletter confirmation links after 48 hours.
- Newsletter: until you unsubscribe (every newsletter has a link). We then keep the address marked as unsubscribed so we don't email it again.
Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California) you can ask to see, correct, export or delete your data, object to or restrict how we use it, and withdraw consent. Email no-reply@ashbornestudios.com from your account's address. We'll answer within one month and won't treat you differently for asking. You can also complain to your local data protection authority. California residents: we don't sell or share personal information for cross-context behavioural advertising.
Security
The site uses HTTPS, hashed passwords and session tokens, encrypted two-factor secrets, mandatory two-factor sign-in for administrators, and rate limits. No system is perfectly secure; if we learn of a breach affecting you, we'll tell you as the law requires.
Children
DEAD AIR is a horror game and the site isn't meant for children under 16. We don't knowingly collect their data.
Changes
If we change this policy we'll update it here, and email account holders about significant changes.